Last updated: 16 August 2026

Data Processing Addendum

This Data Processing Addendum ("DPA") is incorporated into the BuildTrack Terms of Service (the "Terms") and applies when we process personal data in Customer Data on your behalf. Capitalised terms have the meaning in the Terms unless stated here. If you need a signed copy for procurement, email hello@buildtrack.com.my.

1. Roles and scope

You are the data user / controller of personal data in Customer Data. We are your processor. This DPA covers that processing only. It does not cover account, billing or marketing data of which we are the controller, as described in the Privacy Policy.

Subject matter: hosting and processing Customer Data to provide the Service. Duration: the subscription and the post-termination retention described in the Terms. Nature: storage, retrieval, display, backup, transmission to instructed subprocessors, and optional AI inference when you use those features. Types of data and data subjects: as you choose to record — typically contacts, crew, customers and suppliers in Malaysia’s construction industry.

2. Instructions

We will process personal data in Customer Data only on documented instructions: configuring and using the Service, these Terms, this DPA, and lawful written instructions you give us (for example a support request). We will inform you if, in our opinion, an instruction infringes the PDPA, unless the law prohibits that notice. We will not process Customer Data for our own purposes except as the Terms allow (security, law, backups needed to provide the Service).

3. Confidentiality of personnel

People we authorise to process Customer Data are under a duty of confidentiality and may access it only as needed to operate, secure or support the Service.

4. Subprocessors

You authorise us to use the subprocessors listed at BuildTrack subprocessors. Each subprocessor is bound to process data only to provide its service to us, and not for its own marketing, advertising, resale or model training on Customer Data.

We will update that page when we add or replace a material subprocessor. If you object on reasonable data-protection grounds within 15 days of the posting, we will discuss a commercially reasonable workaround. If we cannot agree, you may cancel auto-renewal and stop using the Service as described in the Terms (prepaid fees for the current term are not refunded except where required by law). Continued use after that period without written objection is acceptance of the new subprocessor.

5. Security

We will implement appropriate technical and organisational measures for the nature of the Service, including those summarised on our security page: encryption in transit, tenant isolation by organisation, access control, private file storage, backups, and application security reviews. You are responsible for configuring Authorised User access, passwords, and which integrations you enable.

6. Assistance with requests and PDPA duties

Taking into account the nature of processing, we will assist you with reasonable requests so you can respond to data-subject requests and meet PDPA duties (and, where they apply, comparable overseas duties) relating to Customer Data in the Service. In-product tools are the first path (access, correction and deletion your users can perform). We may charge reasonable costs for assistance beyond ordinary use of the Service.

7. Personal data incidents

We will notify you without undue delay after we confirm a personal-data incident affecting your Customer Data, and will provide information we have so you can meet your own notification duties, including to the Commissioner where the PDPA requires. We will take reasonable steps to contain and remediate. We will not notify regulators or your people on your behalf unless the law requires us to or you instruct us in writing.

8. Return and deletion

During the term and for 30 days after it ends, you may export Customer Data using the export functions available in the Service for your role. After that window we will delete Customer Data from production systems except backups and records we must keep for legal, tax or dispute purposes, which are overwritten in the ordinary backup cycle (typically within 90 days) unless a hold applies.

9. International transfers

You instruct us to transfer personal data in Customer Data to subprocessors in the countries described on the subprocessors page, solely to provide the Service. We use written processor terms with those providers.

10. Information and audits

We will make available information reasonably necessary to demonstrate compliance with this DPA, including the security page and written answers to questionnaires that do not require disclosure of another customer’s data. On-site or invasive audits of production systems are available only if required by applicable law or agreed in a separately signed enterprise order, and must not unreasonably interfere with operations.

11. Liability

Liability under this DPA is subject to the limitations and exclusions in the Terms, including the default cap and the two-times super-cap for confidentiality and personal-data incidents caused by us. This DPA does not create unlimited processor liability.

12. Order of precedence

If this DPA conflicts with the Terms on processing of personal data in Customer Data, this DPA prevails. The Privacy Policy describes our practices; it does not reduce the commitments in this DPA.